5.6mediumMedium

CVE-2025-14087

Gnome Glib

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.

What the metrics mean

  • It is reachable over a network, without needing local access.
  • For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
  • To exploit it, no account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
5.6 (v3.1)
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness
CWE-190
Assigned by
secalert@redhat.com

Dates

Published
2025-12-10
Last modified
2026-08-25
Sources
NVD

Affected products

  • Gnome Glib- 2.86.3
  • Redhat Enterprise Linux7.0, 8.0, 9.0, 10.0

As listed in the NVD configuration data. Not a statement about your estate.

References